CVE-2003-0332
Working Resources BadBlue 1.7.x/2.x - Unauthorized HTS Access
Severity Score
7.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
La extendisón ISAPI en BadBlue 1.7 hasta 2.2, y posiblemente versiones anteriores, modifica las dos primeras letras de la extensión de un archivo después de realizar comprobaciones de seguridad, lo que permite que atacantes remotos pasen la autentificación mediante un fichero .ats en lugar de uno .hts.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2003-05-20 CVE Reserved
- 2003-05-20 First Exploit
- 2003-05-22 CVE Published
- 2023-10-31 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=105346382524169&w=2 | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/22620 | 2003-05-20 | |
http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html | 2024-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Working Resources Inc. Search vendor "Working Resources Inc." | Badblue Search vendor "Working Resources Inc." for product "Badblue" | <= 2.2 Search vendor "Working Resources Inc." for product "Badblue" and version " <= 2.2" | - |
Affected
|